Junglewise Threat Intelligence

CVE-2026-56456: HCL DFXAnalytics internal file path disclosure in dashboard

CVE-2026-56456 · Severity: medium · CVSS 5.3 · Published 2026-07-16

Technologies: HCL Software DFXAnalytics. Vendors: HCL Software.

Executive brief

HCL DFXAnalytics, a data analytics platform, contains a security flaw where the application dashboard reveals internal server file paths to unauthorized users. This information leak occurs through error messages and system logs, allowing a remote attacker to see how the server is organized. While this does not directly grant access to customer data, it provides attackers with a roadmap of the system's internal structure, which can be used to plan more sophisticated attacks.

Technical details

HCL DFXAnalytics version 3.0 and below is vulnerable to information exposure (CWE-200) via internal file path disclosure. The vulnerability exists in the application dashboard, which fails to properly sanitize or suppress verbose error messages, system logs, and debugging output. A remote, unauthenticated attacker can trigger these errors to reveal absolute directory paths and internal file structures of the underlying server. This reconnaissance data can be leveraged to bypass security controls or identify specific locations for secondary attacks, such as local file inclusion or directory traversal. Users are advised to review the HCL security bulletin for patching information.

Affected products

  • HCL Software DFXAnalytics 3.0 and below

Timeline

  • 2026-07-16: advisory: NVD and HCL Software published the vulnerability details.

References

Related threats